← Vulnerability feed

Vulnerability record · CVE-2002-0996 · published 4 October 2002

CVE-2002-0996: Novell netmail vulnerability

Novell · Netmail

Multiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) WebAdmin or (2) ModWeb.

7.5 CVSS 2.0 High EPSS 3.5% · top 11.2%
7.5CVSS 2.0 base score
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) WebAdmin or (2) ModWeb.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0996 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2616Novell netmail vulnerabilityStack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to …EPSS 6.0%9.0CVE-2006-6424Novell NetMail IMAPD and NMAP daemon buffer overflows allow remote code executionNovell NetMail before 3.52e FTF2 contains multiple buffer overflows: a heap overflow in IMAPD triggered by appending literals to certain IMAP verbs d…EPSS 60%analysed9.0CVE-2006-6425Novell NetMail IMAPD APPEND stack buffer overflowNovell NetMail's IMAP daemon (IMAPD) before 3.52e FTF2 contains a stack-based buffer overflow reachable through the APPEND command. A remote authenti…EPSS 58%analysed7.5CVE-2005-3314Novell NetMail IMAP daemon stack buffer overflow via long verb argumentsThe IMAP daemon in Novell NetMail 3.5.2 contains a stack-based buffer overflow (CWE-119) triggered by long verb arguments. A remote, unauthenticated …EPSS 66%analysed7.5CVE-2005-1757Novell netmail vulnerabilityBuffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.EPSS 3.1%7.5CVE-2005-1758Novell netmail vulnerabilityBuffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.EPSS 16%6.8CVE-2007-6302Novell netmail memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in avirus.exe in Novell NetMail 3.5.2 before Messaging Architects M+NetMail 3.52f (aka 3.5.2F) allows remote att…EPSS 5.6%6.8CVE-2007-1350Novell netmail vulnerabilityStack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2002-0996), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.